Fig Security’s pitch is that a quiet security operations center (SOC) is not necessarily a healthy one: changes to telemetry, data pipelines, detection rules or response automation can silently break the chain that turns an event into action. The company says its platform maps those dependencies, alerts teams to risky changes and lets them assess proposed fixes before deployment. Fig announced $38 million in combined seed and Series A funding as it emerged from stealth in March 2026.
What Fig Security is trying to fix
Enterprise security teams rely on a chain of connected systems. Data from security tools and other sources is transformed and routed through pipelines or data lakes, then used by a SIEM and detection logic. An alert may trigger a SOAR platform, another response tool or an AI agent. If a field changes, data stops flowing or a rule no longer matches the data it receives, a detection or response can fail without producing the kind of incident alert analysts expect.
That creates a blind spot: the SOC may appear quiet because defenses are working—or because the systems meant to surface suspicious activity have stopped working. Fig calls its product category Security Operations Resilience and focuses on whether those underlying detection and response paths remain intact.
How Fig says its platform works
Fig says it discovers and maps flows from data sources through pipelines and data lakes to SIEM systems, detection logic and downstream response tools. It observes or samples how data changes along the way, builds data lineage, and uses that map to identify where an upstream change could affect a detection or response. The company describes impact analysis and simulation as ways to assess a proposed fix before it reaches production.
Recommended Free Tools
#1 Best Overall
CEO and co-founder Gal Shafir describes the approach as starting with the detection or response and tracing backward: “Detection or response is the single source of truth, and then we back-trace the health and what needs to happen on the data in order for it to trigger the detection when something happens.”
Two kinds of change the product is designed to track
| Change type | What it means | Why teams may care |
|---|---|---|
| Drift | An unplanned upstream change affects data, a detection rule or an automation. | A detection or response flow may stop working without an obvious incident alert. |
| Planned change | A team intentionally changes infrastructure or tries to improve coverage. | Testing the affected dependencies can help reveal whether an existing flow is at risk before deployment. |
Fig’s framing is therefore broader than checking whether a security tool is online. It is about whether data still has the shape and route needed to activate a particular detection and carry its response through.
Rank #2
What Fig is—and is not—positioned to replace
Fig is presented as a visibility and resilience layer across existing security operations systems, not as a replacement for every SIEM or SOAR product. Its stated differentiator is mapping dependencies from telemetry to detection and response, then flagging changes that could break those links. That makes it adjacent to SIEM, SOAR, security-data-pipeline and detection-observability tools, but the public descriptions do not establish that it replaces those categories.
For a security buyer, the useful question is not simply whether a vendor claims broad integrations. It is whether it can map the specific data paths and dependencies that matter in your environment, explain the likely impact of a change, and support a safe workflow for investigating or testing a fix.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
What buyers should verify
- End-to-end coverage: Ask which data sources, pipelines, data lakes, SIEMs, response systems and AI agents Fig supports in your environment. A complete integration list has not been publicly identified.
- Failure detection: Establish how the platform distinguishes a real break in a detection or response path from a harmless data change, and how it communicates root cause.
- Change testing: Ask what a simulation actually evaluates, what evidence it produces, and how teams can use it before a migration, schema update, patch or coverage change.
- Operational fit: Confirm deployment effort, data access requirements, alert handling and how remediation fits the team’s current workflows.
- Proof of value: Request customer references and measured outcomes relevant to your use case. Public launch coverage does not provide named customers or independently audited performance benchmarks.
- Commercial terms: Pricing and contract terms have not been publicly stated in the launch coverage.
Funding, founders and reported traction
Fig announced $38 million in combined seed and Series A financing, led by Team8 and Ten Eleven Ventures, with participation from security-industry executives and founders, according to TechCrunch. The company was founded in March 2025 by Gal Shafir, Nir Loya Dahan and Roy Haimof. Shafir is CEO and previously led Google Cloud Security’s global architecture team and held leadership roles at Siemplify. Dahan, the chief product officer, previously held product leadership roles at Cymulate and Siemplify; Haimof, the CTO, was a director of engineering at Cymulate. Launch coverage describes the founders as veterans of Israeli intelligence units 8200 and Mamram.
TechCrunch reported low-double-digit large-enterprise customers and said management was targeting 50–100 customers by the end of 2026. Those figures are company-reported traction and a management target, not an independent audit or a guarantee of future growth. The company also said it planned to expand engineering and go-to-market operations, particularly in North America.
Rank #4
Why the idea matters beyond Fig
Security operations depend on more than the quality of detection rules. Those rules need the right data, in the expected format, delivered through functioning infrastructure, and connected to a response workflow. As environments change, checking only whether tools are running can miss failures in the links between them. Fig’s central proposition is that those dependencies should be monitored as part of security operations, so that silence is less likely to be mistaken for safety.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors

